Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Number19
May 14, 2003

HOCKEY OWNS
FUCK YEAH


fishmech posted:

so is the windows defender thing meant to be the same as this
https://twitter.com/taviso/status/860681252034142208

or is that a second major thing that hasn't been announced yet. cuz the wording is kind of a bit more dire than what actually got announced (since a lot of default windows installs are going to be with some crap like Norton installed and defender disabled, let alone all the 7 and older machines out there which are still the majority of windows installs

(windows versions that had modern defender installed by default are currently about 38% of Windows systems online)

yes, that's it. the project zero bug for it is public now as was linked upthread.

the cumulative updates for windows 10 RTM, 1511, and 1607 have not been published so far today while the 1703 one has so there must be something else up that's causing a delay.

Adbot
ADBOT LOVES YOU

James Baud
May 24, 2015

by LITERALLY AN ADMIN

haveblue posted:

it can be triggered by automated inbound data like email bodies, IMs, etc

I was thinking that made it a bit of a reach on servers, but I guess Exchange does exist and has the option of automatic AV scanning.

I think it was slightly oversold between wormable and default install... Because things like that have happened before to fully patched systems, granted not in ~15 years.

akadajet
Sep 14, 2003

Number19 posted:

yes, that's it. the project zero bug for it is public now as was linked upthread.

the cumulative updates for windows 10 RTM, 1511, and 1607 have not been published so far today while the 1703 one has so there must be something else up that's causing a delay.

this morning I had a patched version of the windows defender runtime already :shrug:

Number19
May 14, 2003

HOCKEY OWNS
FUCK YEAH


akadajet posted:

this morning I had a patched version of the windows defender runtime already :shrug:

yes, the defender update is out. the regular patch tuesday updates for windows 10 RTM, 1511, and 1607 haven't hit my WSUS yet even though 1703 has :shrug:

30 TO 50 FERAL HOG
Mar 2, 2005



James Baud posted:

I was thinking that made it a bit of a reach on servers, but I guess Exchange does exist and has the option of automatic AV scanning.

I think it was slightly oversold between wormable and default install... Because things like that have happened before to fully patched systems, granted not in ~15 years.

if you arent exempting exchange dirs from AV you're gonna have a bad time

https://gallery.technet.microsoft.com/office/Generate-Antivirus-f1a9a59e

theres a powershell script to do it for you by an MVP

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer
i mean one of the money quotes from the report is literally:

quote:

Extra care should be taken sharing this report with other Windows users via Exchange, or web services based on IIS, and so on.

ultramiraculous
Nov 12, 2003

"No..."
Grimey Drawer

haveblue posted:

corporate IT forced me to install an awful AV package that greatly increased build times, so I broke it by messing around in terminal and they got tired of trying to unbreak it

(they tried to fix the build time issue themselves a couple of times but it never took)

yeah I had a pretty identical situation recently. it peaked for me when I got a very polite email from IT asking why their management software asking if there was a problem with my machine, because Sophos was stuck trying to install itself infinitely 😅

cinci zoo sniper
Mar 15, 2013




https://www.invincea.com/datasheets/invincea-machine-learning ehhhh

cinci zoo sniper
Mar 15, 2013




catching up on news. i guess im the 900 grand fbi paid to buy an ios 0day from israelis

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Truga
May 4, 2014
Lipstick Apathy

nice!

flakeloaf
Feb 26, 2003

Still better than android clock

https://twitter.com/_lennart/status/861714732709031936

something something raw lightsockets

YO MAMA HEAD
Sep 11, 2007

hasn't he ever heard of onion bulbs

JawnV6
Jul 4, 2004

So hot ...
ntp tho?

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner

YO MAMA HEAD posted:

hasn't he ever heard of onion bulbs

Meat Beat Agent
Aug 5, 2007

felonious assault with a sproinging boner
also: https://security.stackexchange.com/questions/158802/how-can-this-executable-have-an-avi-extension

unicode :argh:

flakeloaf
Feb 26, 2003

Still better than android clock

YO MAMA HEAD posted:

hasn't he ever heard of onion bulbs

Nice!

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

YO MAMA HEAD posted:

hasn't he ever heard of onion bulbs
some extremely choice quotes itt

redleader
Aug 18, 2005

Engage according to operational parameters

loving lol. this is a great future we're building here

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

redleader posted:

loving lol. this is a great future we're building here
no one's going to post the reply he makes to his own tweet where he goes "oh that's the ntp server i set up on my modem which is using openwrt. that's the openwrt ntp servers." are they

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
https://twitter.com/_lennart/status/861716107002077184 surprisingly this is not an iot fuckup

Proteus Jones
Feb 28, 2013




Holy poo poo that's fiendishly clever.

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum
on the other hand this tweet is far more interesting https://twitter.com/aikii/status/862008738659659783

flakeloaf
Feb 26, 2003

Still better than android clock

anthonypants posted:

no one's going to post the reply he makes to his own tweet where he goes "oh that's the ntp server i set up on my modem which is using openwrt. that's the openwrt ntp servers." are they

:doh:

A Pinball Wizard
Mar 23, 2005

I know every trick, no freak's gonna beat my hands

College Slice



:vince:

Shame Boy
Mar 2, 2010

anthonypants posted:

on the other hand this tweet is far more interesting https://twitter.com/aikii/status/862008738659659783

im Female-Young adult, Attention time: 219

ate shit on live tv
Feb 15, 2004

by Azathoth

Glad I'm back in 1995, regularly downloading porn_movie.avi.exe.com.swf again.

Shame Boy
Mar 2, 2010


oh that's real cute

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

ate poo poo on live tv posted:

Glad I'm back in 1995, regularly downloading porn_movie.avi.exe.com.swf again.

Daman
Oct 28, 2011
Does anyone know the process to get AV companies to care about some malware? Doing IR for this hopeless company that got hosed by a certain nation state, they had like four different implants, only one of which is being detected by like 6 on virustotal. The rest are totally not detected, but these binaries are not even obfuscated. Lots of strings and debug strings. That one is a Remexi implant, Symantec did a writeup on Remexi, wrote a report with YARA signatures. Symantec endpoint protection, installed on all of their hosts, failed to detect it.

Like one of these hits Google Drive and calls createprocess after downloading whatever new poo poo. How is there not a heuristic "Internet connectivity, and then this process spawned cmd.exe as a child"! AV is loving worthless.

But there's got to be some way to get Symantec to trigger on these samples at least, right?

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



ate poo poo on live tv posted:

Glad I'm back in 1995, regularly downloading porn_movie.avi.exe.com.swf again.

i think u mean porn_movie.avi.exe.com.nsfw

spankmeister
Jun 15, 2008






Daman posted:

Does anyone know the process to get AV companies to care about some malware? Doing IR for this hopeless company that got hosed by a certain nation state, they had like four different implants, only one of which is being detected by like 6 on virustotal. The rest are totally not detected, but these binaries are not even obfuscated. Lots of strings and debug strings. That one is a Remexi implant, Symantec did a writeup on Remexi, wrote a report with YARA signatures. Symantec endpoint protection, installed on all of their hosts, failed to detect it.

Like one of these hits Google Drive and calls createprocess after downloading whatever new poo poo. How is there not a heuristic "Internet connectivity, and then this process spawned cmd.exe as a child"! AV is loving worthless.

But there's got to be some way to get Symantec to trigger on these samples at least, right?

AV vendors all share samples and have VT feeds, so if you submit it at VT it will get picked up.

Daman
Oct 28, 2011
I would think Symantec probably takes ages to detect new stuff from feeds, there's gotta be some high priority channel...

Wiggly Wayne DDS
Sep 11, 2010



Daman posted:

I would think Symantec probably takes ages to detect new stuff from feeds, there's gotta be some high priority channel...
virustotal is a high priority channel, just make sure it's flagged appropriately

Powerful Two-Hander
Mar 10, 2004

Mods please change my name to "Tooter Skeleton" TIA.


hmmm. our hr system will generate you a pdf of your pay and the filename just appears to be [your id]_filename_[some number].pdf which is passed as a get request from the browser.

it prompts for logon but what is the betting that a)once logged on it does not check if the logged on user has access to that doc so you can traverse the file names and b) i will get fired if i try to test this out

pseudorandom name
May 6, 2007

Powerful Two-Hander posted:

i will get fired if i try to test this out

well, we all know the motto of the secfuck thread: "just touch the poop. really get in there and squeeze until it oozes through the gaps between your fingers"

FAT32 SHAMER
Aug 16, 2012



Powerful Two-Hander posted:

hmmm. our hr system will generate you a pdf of your pay and the filename just appears to be [your id]_filename_[some number].pdf which is passed as a get request from the browser.

it prompts for logon but what is the betting that a)once logged on it does not check if the logged on user has access to that doc so you can traverse the file names and b) i will get fired if i try to test this out

What if you try it out with a figure whos salary is public facing, then bring it to HR as a security issue

cinci zoo sniper
Mar 15, 2013




funny Star Wars parody posted:

What if you try it out with a figure whos salary is public facing, then bring it to HR as a security issue
you can still get perfectly hosed :shrug:

FAT32 SHAMER
Aug 16, 2012



cinci zoo sniper posted:

you can still get perfectly hosed :shrug:

Oh yeah for sure, i'm just trying to give him a stick to poke at it

Adbot
ADBOT LOVES YOU

cinci zoo sniper
Mar 15, 2013




funny Star Wars parody posted:

Oh yeah for sure, i'm just trying to give him a stick to poke at it
i dont think there is a safe stck to poke other than, if it really bugs you, to email security dept with cc to hr dept that you have observed this and that and you wonder should you be concerned with privacy of your earnings or something

  • Locked thread